CRA-Ready SBOMs: A Practical Blueprint for High-Quality Generation
- Track: SBOMS and supply chains
- Room: UD2.208 (Decroly)
- Day: Sunday
- Start: 11:30
- End: 12:00
- Video only: ud2208
- Chat: Join the conversation!
As one of the co-leaders of the CISA working group on SBOM Generation and a contributor to its accompanying whitepaper, I’ve spent the last few years deep in the trenches of SBOM creation. With the EU’s Cyber Resilience Act (CRA) raising the bar for software transparency and lifecycle security, the need for reliable, high-quality SBOMs has never been more urgent.
In this talk, I’ll present a practical blueprint for SBOM generation that goes beyond minimal compliance and helps projects prepare for the expectations emerging from the CRA and similar regulatory frameworks. The model breaks SBOM creation into four clear phases:
- Authoring – producing the initial SBOM from a lockfile
- Augmenting – resolving gaps and adding metadata to meet increasingly strict transparency requirements that SBOM generation tools can't do
- Enriching – improve the quality of the SBOM using open data sets
- Signing – provide attestation to ensure the SBOM can be trusted
I’ll discuss the technical considerations behind each phase, common pitfalls, and how these practices help projects avoid the compliance gaps many teams are now discovering as the CRA timeline approaches.
To ground everything in reality, I’ll also demo an open-source implementation of this entire workflow that runs directly inside GitHub Actions (or any CI environment), enabling maintainers to adopt a CRA-ready SBOM pipeline without proprietary tools.
Speakers
| Viktor Petersson |